🇿🇦
conure.sh
2026-09-15 12:03:00
(5 minutes ago)
csagent: score 20.7: 404 noise floor x3, secrets grab x2; 2 domain(s) in -7h29m41s
Web App Attack
🇧🇪
taivas.nl
2026-09-15 04:33:22
(7 hours ago)
Many_bad_calls
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 03:31:49
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.196.121.14 (ec2-54-196-121-14.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 54.196.121.14 (ec2-54-196-121-14.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 23:31:44.312794 2026] [security2:error] [pid 16146:tid 16146] [client 54.196.121.14:56698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.monogay.org"] [uri "/wp-config.php.bak"] [unique_id "aqi8IC36FxiUdIllZln5ZgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 02:52:18
(9 hours ago)
CPOWCO WEBEXPLOIT 54.196.121.14 (ec2-54-196-121-14.compute-1.amazonaws.com)
Web App Attack
Anonymous
2026-09-15 01:47:56
(10 hours ago)
Web application attack detected.
Web App Attack
🇭🇷
bubausluge
2026-09-14 23:47:38
(12 hours ago)
Blocked by https://aegis.hr — Web Scanner - (MITRE T1595.001), 91 attempts, Period: 2026-09-14 10:34 ...
show more
Blocked by https://aegis.hr — Web Scanner - (MITRE T1595.001), 91 attempts, Period: 2026-09-14 10:34:28 to 2026-09-14 10:37:29
show less
Web App Attack
Bad Web Bot
🇩🇪
FeG Deutschland
2026-09-14 23:35:26
(12 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 22:51:44
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.196.121.14 (ec2-54-196-121-14.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 54.196.121.14 (ec2-54-196-121-14.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 18:51:38.211014 2026] [security2:error] [pid 11624:tid 11624] [client 54.196.121.14:53852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.batesstrategygroup.com"] [uri "/wp-config.php~"] [unique_id "aqh6emR33jsT_63BdsF0XgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 20:13:13
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.196.121.14 (ec2-54-196-121-14.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 54.196.121.14 (ec2-54-196-121-14.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 16:13:05.752656 2026] [security2:error] [pid 25139:tid 25139] [client 54.196.121.14:43990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crr-construction.com"] [uri "/wp-config.php.orig"] [unique_id "aqhVUbmP9ZsP3t21IJGHdQAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-14 20:11:34
(15 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: apm.astropot.online | URI: /.env.txt | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 19:50:16
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.196.121.14 (ec2-54-196-121-14.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 54.196.121.14 (ec2-54-196-121-14.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 15:50:08.716921 2026] [security2:error] [pid 3235210:tid 3235210] [client 54.196.121.14:55146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dynamic-therapy-mn.com"] [uri "/wp-config.php.bak"] [unique_id "aqhP8DJmLVhvjQWlnbvLbAAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 18:10:22
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.196.121.14 (ec2-54-196-121-14.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 54.196.121.14 (ec2-54-196-121-14.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 14:10:17.752284 2026] [security2:error] [pid 32078:tid 32092] [client 54.196.121.14:48498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.thesdgriffingroup.com"] [uri "/wp-config.php.save"] [unique_id "aqg4iXHB41HLvOG4TUg1EQAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-14 17:56:44
(18 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TAY
2026-09-14 17:16:07
(18 hours ago)
54.196.121.14 - - [15/Sep/2026:01:15:24 +0800] "GET /wp-config.php~ HTTP/1.1" 301 6132 "-" "Mozilla/ ...
show more
54.196.121.14 - - [15/Sep/2026:01:15:24 +0800] "GET /wp-config.php~ HTTP/1.1" 301 6132 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
54.196.121.14 - - [15/Sep/2026:01:15:25 +0800] "GET /wp-config.php~ HTTP/1.1" 404 46396 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
54.196.121.14 - - [15/Sep/2026:01:15:27 +0800] "GET /wp-config.php.save HTTP/1.1" 301 6136 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
54.196.121.14 - - [15/Sep/2026:01:15:33 +0800] "GET /wp-config.php.save HTTP/1.1" 404 46396 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
54.196.121.14 - - [15/Sep/2026:01:16:05 +0800] "GET /wp-config.php.orig HTTP/1.1" 301 6136 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like
...
show less
Brute-Force
🇩🇪
gadix
2026-09-14 16:42:38
(19 hours ago)
[14/Sep/2026:18:42:36.560290 +0200] aqgj_MuRlOyhFEFM5l0ldAAAAAU 54.196.121.14 38708 127.0.0.1 7081
[ ...
show more
[14/Sep/2026:18:42:36.560290 +0200] aqgj_MuRlOyhFEFM5l0ldAAAAAU 54.196.121.14 38708 127.0.0.1 7081
[14/Sep/2026:18:42:36.686270 +0200] aqgj_BVtK5z2xEeGPqvaLAAAAAI 54.196.121.14 38712 127.0.0.1 7081
[14/Sep/2026:18:42:36.846606 +0200] aqgj_GlWcN2IyHnHO84PHQAAAAc 54.196.121.14 38726 127.0.0.1 7081
...
show less
Web App Attack